VYPR

Vios

by IBM

CVEs (92)

  • CVE-2025-36250CriNov 13, 2025
    risk 0.65cvss 10.0epss 0.01

    IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to execute arbitrary commands due to improper process controls.  This addresses additional attack vectors for a vulnerability that was…

  • CVE-2025-36251CriNov 13, 2025
    risk 0.62cvss 9.6epss 0.01

    IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due to improper process controls. This addresses additional attack vectors for a vulnerability that was previously addressed in…

  • CVE-2025-36096CriNov 13, 2025
    risk 0.59cvss 9.0epss 0.00

    IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthorized access by an attacker using man in the middle techniques.

  • CVE-2023-28528HigApr 28, 2023
    risk 0.58cvss 8.4epss 0.01

    IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 251207.

  • CVE-2022-22351HigMar 7, 2022
    risk 0.56cvss 8.6epss 0.01

    IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged trusted host user to exploit a vulnerability in the nimsh daemon to cause a denial of service in the nimsh daemon on another trusted host. IBM X-Force ID: 220396

  • CVE-2025-33112HigJun 10, 2025
    risk 0.55cvss 8.4epss 0.00

    IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary code due to improper neutralization of pathname input.

  • CVE-2024-27260HigMay 16, 2024
    risk 0.55cvss 8.4epss 0.00

    IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 283985.

  • CVE-2024-25021HigFeb 22, 2024
    risk 0.55cvss 8.4epss 0.00

    IBM AIX 7.3, VIOS 4.1's Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary commands. IBM X-Force ID: 281320.

  • CVE-2023-45174HigDec 13, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a privileged local user to exploit a vulnerability in the qdaemon command to escalate privileges or cause a denial of service. IBM X-Force ID: 267972.

  • CVE-2023-45170HigDec 13, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the piobe command to escalate privileges or cause a denial of service. IBM X-Force ID: 267968.

  • CVE-2023-45166HigDec 13, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the piodmgrsu command to obtain elevated privileges. IBM X-Force ID: 267964.

  • CVE-2023-45168HigDec 1, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 267966.

  • CVE-2023-26286HigApr 26, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX runtime services library to execute arbitrary commands. IBM X-Force ID: 248421.

  • CVE-2022-41290HigDec 23, 2022
    risk 0.55cvss 8.4epss 0.00

    IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the rm_rlcache_file command to obtain root privileges. IBM X-Force ID: 236690.

  • CVE-2016-8972HigFeb 15, 2017
    risk 0.54cvss 7.8epss 0.01

    IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: IV91006, IV91007, IV91008, IV91010, IV91011.

  • CVE-2016-6079HigFeb 15, 2017
    risk 0.54cvss 7.8epss 0.02

    IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM APARs: IV88658, IV87981, IV88419, IV87640, IV88053.

  • CVE-2025-36236HigNov 13, 2025
    risk 0.53cvss 8.2epss 0.00

    IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to write arbitrary files on the system.

  • CVE-2024-27273HigMay 7, 2024
    risk 0.53cvss 8.1epss 0.00

    IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose applications using Unix domain datagram sockets with SO_PEERID operation and may lead to privilege escalation. IBM X-Force ID: 284903.

  • CVE-2024-47115HigDec 7, 2024
    risk 0.51cvss 7.8epss 0.00

    IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improper neutralization of input.

  • CVE-2022-36768HigSep 13, 2022
    risk 0.51cvss 7.8epss 0.00

    IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to obtain root privileges. IBM X-Force ID: 232014.

Page 1 of 5